- Attackers cloned AI skills, later adding malicious code to steal credentials
- Zenity Labs found millions of installs and dozens of dangerous skill variants
- Vercel and Microsoft removed malicious skills, but manual removal is still required
AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.